Exploitation Summary
EIP tracks 2 public exploits for CVE-2015-5453.
PoCs published by Metasploit, including Metasploit module exploits/freebsd/http/watchguard_cmd_exec.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated SQL injection to add a backdoor user and a command injection vulnerability in Watchguard XCS to achieve remote command execution as the 'nobody' user.
Description
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.
Exploits (2)
This Metasploit module exploits an unauthenticated SQL injection to add a backdoor user and a command injection vulnerability in Watchguard XCS to achieve remote command execution as the 'nobody' user.
This Metasploit module exploits an unauthenticated SQL injection (CVE-2015-5453) to add a backdoor user and then leverages a command injection vulnerability in the Watchguard XCS web interface to achieve remote command execution as the 'nobody' user.